Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

PyPCAPKit -- Comprehensive Network Packet Analysis Library

For any technical and/or maintenance information, please kindly refer to the Official Documentation.

The PyPCAPKit project is an open source Python program focused on network packet parsing and analysis, which works as a comprehensive PCAP file extraction, construction and analysis library, with DictDumper as its formatted output dumper.

Unlike popular PCAP file extractors such as Scapy, DPKT and PyShark, pcapkit is designed to be much more comprehensive: it reports more detailed information about each packet, and offers a more Pythonic interface to work with it. When that depth is not what you need, the same interface will also drive six third-party extraction engines instead.

The whole project supports Python 3.6 or later.

Installation

pip install pypcapkit

Or from a clone, for the latest version and for development:

git clone https://github.com/JarryShaw/PyPCAPKit.git
cd PyPCAPKit
pip install -e .

The extraction engines and plug-ins are optional extras:

pip install pypcapkit[DPKT]         # or Scapy, PyShark, PyPCAPFile, PyPCAP, PCAP_CT
pip install pypcapkit[crypto]       # ESP payload decryption
pip install pypcapkit[cli]          # command line interface
pip install pypcapkit[all]          # every pure-Python extra

Four of the engines need something beyond a pip install -- a tshark binary, a C compiler, libpcap headers, or an older interpreter -- and all deliberately excludes both pypcap and pcap-ct, which must never be installed together. The installation guide covers every constraint and the reason for it, and pcapkit enforces each one in code: asking for an engine that cannot run in the current environment warns with the actual cause and falls back to pcapkit's own parser.

Usage

>>> import pcapkit
>>> extraction = pcapkit.extract('in.pcap', nofile=True)
>>> len(extraction.frame)
6
>>> frame = extraction.frame[0]
>>> str(frame.protochain)
'Ethernet:IPv6:IPv6_ICMP'
>>> frame.info.time
datetime.datetime(2017, 11, 19, 15, 49, 5, 471719, tzinfo=datetime.timezone.utc)
>>> frame.payload.payload.src
IPv6Address('fe80::a6:87f9:2793:16ee')

The output above is from examples/captures/in.pcap, which is committed, so it is reproducible from a clone.

Reassembly, TCP flow tracing and a different engine are all keyword arguments on the same call:

>>> scapy = pcapkit.extract('in.pcap', nofile=True, engine='scapy')
>>> reasm = pcapkit.extract('in.pcap', nofile=True, reassembly=True, ipv6=True)
>>> flows = pcapkit.extract('in.pcap', nofile=True, trace=True, tcp=True)
>>> len(flows.trace)
3

More worked examples, including the command line interface, are in How to ....

Documentation

The official documentation is the reference for everything below. The pages worth knowing by name:

Page What is in it
API reference Every module, protocol and constant
Module structure What each of the eight subpackages is for
Engine comparison Which engines exist, which Python versions they run on, and measured speed per packet
Engine support What each engine does not support, and how the gap is surfaced
Installation Extras, engine prerequisites and the local development setup
Testing Running the suite, and the sample captures it needs
How to ... Worked examples, library and CLI
Extensions Registering your own protocols, engines and dumpers

Release history is in CHANGELOG.md, and contribution guidelines are in CONTRIBUTING.md.

Metadata

Release files for pypcapkit 1.5.0b6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypcapkit 1.5.0b6
File Size Uploaded
pypcapkit-1.5.0b6.tar.gz 2.7 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for pypcapkit 1.5.0b6
File
pypcapkit-1.5.0b6-pp311-none-any.whl PyPy 3.11 none any Details
pypcapkit-1.5.0b6-pp310-none-any.whl PyPy 3.10 none any Details
pypcapkit-1.5.0b6-cp314-none-any.whl CPython 3.14 none any Details
pypcapkit-1.5.0b6-cp313-none-any.whl CPython 3.13 none any Details
pypcapkit-1.5.0b6-cp312-none-any.whl CPython 3.12 none any Details
pypcapkit-1.5.0b6-cp311-none-any.whl CPython 3.11 none any Details
pypcapkit-1.5.0b6-cp310-none-any.whl CPython 3.10 none any Details

Total release size: 14.1 MB

Release files / pypcapkit-1.5.0b6.tar.gz

Download URL pypcapkit-1.5.0b6.tar.gz
Size 2.7 MB
Tags Source
SHA-256 checksum
How to use checksums
47e34fe6b34c01168d25667a7b7f9c6723ee23c9220152844b2e507b19874e41
BLAKE2b-256 checksum
How to use checksums
c53763767c34c1c53334b2d5dee841d3ee70b088546ab3c8efd50327953864dc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-pp311-none-any.whl

Download URL pypcapkit-1.5.0b6-pp311-none-any.whl
Size 1.6 MB
Tags PyPy 3.11
SHA-256 checksum
How to use checksums
c7da29ee3ba2e9ed255fb5cde08930d52026370c9883bd60cc3e2f566dfb818f
BLAKE2b-256 checksum
How to use checksums
bb18180709d7a30af9034dcdbbb8051e9dc63ffc58d4fe0138a2c0e08c1d1462
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-pp310-none-any.whl

Download URL pypcapkit-1.5.0b6-pp310-none-any.whl
Size 1.6 MB
Tags PyPy 3.10
SHA-256 checksum
How to use checksums
dd77fba2ccafcbd8552e605ca58f504de8b0dc6b3cd40845fbfa945a632ab51d
BLAKE2b-256 checksum
How to use checksums
01592359a28c33af227142dd4d4715037300ad5f9c41f874b949ed491b12244e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-cp314-none-any.whl

Download URL pypcapkit-1.5.0b6-cp314-none-any.whl
Size 1.6 MB
Tags CPython 3.14
SHA-256 checksum
How to use checksums
b205b417d23c5c8bb6a9e9dbeb8b465733da9330a73916a920bf4d92f0cb487e
BLAKE2b-256 checksum
How to use checksums
ad8ce0c3dd9a2dc996c7f4f92330475740c98b60e665bcf3f8c36947fa32d7a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-cp313-none-any.whl

Download URL pypcapkit-1.5.0b6-cp313-none-any.whl
Size 1.6 MB
Tags CPython 3.13
SHA-256 checksum
How to use checksums
f049c3d66534e555d75b22289a9fa8e2b380852a22650c5f4642758179e842ab
BLAKE2b-256 checksum
How to use checksums
20b2b085e26cd3849cdd9091ff8c57651507646ac675a9aa009555f770b81d27
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-cp312-none-any.whl

Download URL pypcapkit-1.5.0b6-cp312-none-any.whl
Size 1.6 MB
Tags CPython 3.12
SHA-256 checksum
How to use checksums
b42f35b15445fd35c74e65c3c0f490c89784e04e28d36d2b681ad7894d2a4087
BLAKE2b-256 checksum
How to use checksums
4b4cea29b26b2d67da3d2e97beabf61245640e443802fa48ee8e403916d542b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-cp311-none-any.whl

Download URL pypcapkit-1.5.0b6-cp311-none-any.whl
Size 1.6 MB
Tags CPython 3.11
SHA-256 checksum
How to use checksums
95f75879df2ce235a19c3611ebea891a2948606936373e7231da1cd0100e56b5
BLAKE2b-256 checksum
How to use checksums
61fc5e3ae475f058e2ecc75d3700325da0e479477b65dbcc26c931f3105828af
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b6-cp310-none-any.whl

Download URL pypcapkit-1.5.0b6-cp310-none-any.whl
Size 1.6 MB
Tags CPython 3.10
SHA-256 checksum
How to use checksums
7879f6289818659fd0eb4818a382999748ea1556da6865170055a53b114de2b7
BLAKE2b-256 checksum
How to use checksums
36f05d45400e77dd3703b947a12b28f5bc0cf8754fc3aebb58d6e21bc969773e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.5.0b6 This release

8 release files

1.4.1

8 release files

1.4.0

8 release files

1.3.5

8 release files

1.3.4

9 release files

1.3.3

7 release files

1.3.1

6 release files

1.3.0

7 release files

1.2.2

6 release files

1.2.1

7 release files

1.2.0

7 release files

1.1.1

7 release files

1.1.0

7 release files

1.0.3

6 release files

1.0.2

5 release files

1.0.1

2 release files

1.0.0

2 release files

0.16.2

1 release file

0.16.1

1 release file

0.16.0

1 release file

0.15.5

2 release files

0.15.4

2 release files

0.15.3

2 release files

0.15.2

2 release files

0.15.1

2 release files

0.12.9

3 release files

0.12.8

3 release files

0.12.7

3 release files

0.12.6

3 release files

0.12.5

2 release files

0.12.2

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.11.3

2 release files

0.11.2

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.10

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page